CVE-2014-2130: Cisco Secure Access Control System

Medium severity, CVSS 6.5. EPSS: 4% chance of exploitation in the next 30 days.

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.

Affected products

  • Cisco Secure Access Control System: affected versions not specified

Published 2015-03-06. Last modified 2026-06-17.